PT-2013-2053 · Microsoft · Windows Forms+1
Published
2013-01-09
·
Updated
2023-12-07
·
CVE-2013-0002
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft .NET Framework versions 1.0 SP3 through 4.5
Description
A buffer overflow issue in the Windows Forms component allows remote attackers to execute arbitrary code via a crafted XAML browser application or a .NET Framework application. This is due to improper counting of objects during a memory copy operation. An elevation of privilege vulnerability also exists in the way a Windows Forms method validates the number of objects in memory before copying those objects into an array. If exploited, an attacker could take complete control of an affected system, install programs, view, change, or delete data, or create new accounts with full user rights.
Recommendations
For Microsoft .NET Framework versions 1.0 SP3 through 4.5, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
.Net Framework
Windows Forms